The analysis conducted by an organizational official to determine the extent to which changes to the information system have affected the security state of the system.
Sources:
NIST SP 800-137
under Security Impact Analysis
NIST SP 800-30 Rev. 1
under Security Impact Analysis
NIST SP 800-39
under Security Impact Analysis
The analysis conducted by an organizational official to determine the extent to which a change to the information system has or may have affected the security posture of the system.
Sources:
NIST SP 800-128
under Security Impact Analysis
from
CNSSI 4009 - Adapted
The analysis conducted by an agency official, often during the continuous monitoring phase of the security certification and accreditation process, to determine the extent to which changes to the information system have affected the security posture of the system.
Sources:
NIST SP 800-18 Rev. 1
under Security Impact Analysis